The hottest topic in the world these days is undoubtedly the war between Russia and Ukraine. In addition to major companies around the world announcing that they will stop dealings with Russia, many companies have been greatly affected because their parts production centers are located in Ukraine. In order to be able to deal with emergencies, everyone exchanges letters very frequently. Unscrupulous people have seized on people’s nervousness and fear, and tricked you into downloading problematic attachments in the name of the war between Russia and Ukraine.

The Russia-Ukraine war has become a new fishing trick for unscrupulous people. Be careful when downloading attachments in business transactions.
The security research unit Bitdefender Labs has been tracking two different phishing activities since early March. Both of them are using the name of the Russia-Ukraine war that is currently attracting global attention. They are phishing users on the Internet or defrauding them of money. Everyone must be particularly careful not to let their kindness be taken advantage of.
Fishing aimed at manufacturing business cooperation
Since Ukraine is one of the global manufacturing centers for various parts, the current conflict between the two countries has forced the closure of many factories and inevitably caused supply shortages and supply chain disruptions. The first type of phishing campaign discovered by Bitdefender Labs targeted manufacturers, sending out letters that first offered greetings and then stated that they were filling customers with backup production options and wanted you to download an attachment to complete their questionnaire.

But this seemingly well-intentioned email actually contained a malicious attachment. The Zip archive contains the Agent Tesla RAT, a data-stealing Trojan that has been heavily used in various phishing campaigns in the past. 85% of this type of advertising phishing emails come from the Netherlands, and the current main targets are the Czech Republic (14%), South Korea (23%), Germany (10%), the United Kingdom (10%) and the United States (8%).
Fake orders reserved
The second activity involved a South Korean healthcare company that counterfeited the production of in vitro diagnostic systems. In a letter sent to Target, it was written that due to flight and transportation restrictions to and from Ukraine, all orders are currently on hold. The attached Excel file supposedly contains more order details, but in fact it is just a macro that exploits a Microsoft Office Equation Editor bug that was popular four years ago to deliver Remcos RAT on the system.

89% of these emails originated from German IP addresses and were primarily targeted in Ireland (32%), India (17%) and the United States (7%).
Crypto Donation Scam
The Bitdefender report also mentioned that some unscrupulous individuals tried to convince users in their letters that they were legitimate charities and hoped that users would donate money to support Ukraine. These scams are getting more and more popular, with malicious actors impersonating organizations including the Ukrainian government, UNICEF, World Peace Organization and the Ukraine Disaster Relief Fund.

The main themes of the letters they use are nothing more than helping Ukrainian children, helping Ukraine stop the war, etc., and they hope that everyone will click on the links inside or make donations through cryptocurrency. I would like to remind everyone that if you really want to donate to Ukraine, please consider donating directly to official units or large organizations such as the Ukrainian Red Cross. The Ukrainian government also posted on Twitter to provide official cryptocurrency donation methods.
Stand with the people of Ukraine. Now accepting cryptocurrency donations. Bitcoin, Ethereum and USDT.
BTC – 357a3So9CbsNfBBgFYACGvxxS6tMaDoa1P
ETH and USDT (ERC-20) – 0x165CD37b4C644C2921454429E7F9358d18A45e14
— Ukraine / Україна (@Ukraine) February 26, 2022
Source: KOCPC Chinese